CrowdStrike
crowdstrike.com › en-us › resources › data-sheets › falcon-complete-identity-threat-protection
Falcon Complete Identity Threat Protection Data Sheet
July 2, 2024 - Falcon Complete ITP is the first and only fully managed identity protection solution, delivering frictionless, real-time identity threat prevention and IT policy enforcement, with expert management, monitoring and remediation.
CrowdStrike
crowdstrike.com › platform › next-gen identity security › identity protection
AI-Powered Identity Protection for Hybrid Environments | CrowdStrike
3 weeks ago - Protect hybrid identities with CrowdStrike Falcon® Identity Protection. Leverage AI-driven detection, response, and zero standing privilege access control.
Falcon Identity Threat Protection (ITP) Risk factors descriptions
Hey new poster! We require a minimum account-age and karma for this subreddit. Remember to search for your question first and try again after you have acquired more karma. I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns. More on reddit.com
The ReadOut: Falcon Identity Threat Protection (23:30)
What's approximate pricing for Falcon Identity Threat Protection?
More on reddit.comCrowdStrike Falcon Identity Protection still available or integrated in Falcon sensor?
Hi there. You have to buy a license for Identity Threat Protection, but the code-base is included in the Falcon Sensor (you don't need to install something else). ITP will inspect authentication traffic that is traversing your domain controllers to provide enforcement for step-up multi-factor authentication and collects additional data that can be used to detect identity specific threats. I hope that helps! More on reddit.com
Identity Threat Protection questions.
Any on-premise accounts whose domains are not integrated with Azure AD will need to use a different MFA than the Azure AD MFA. We have this problem too; we're considering just using an RFC 6238 compliant TOTP (which includes the MS Authenticator app) and making sure the user is coming from an endpoint with CS Falcon installed. Falcon will pop-up a requeste for the TOTP and the user has to get it from the authenticator app on their phone. The lack of a prompt won't be a problem for Azure AD integrated domains, as that will use the Phone Authenticator (if you have that configured) I didn't know there was a difference between the two. Ours uses Azure AD MFA as defined in our "Authentication Methods" settings in Azure AD. This is set as number matching Phone Sign-In Yes, we use native Azure AD-joined devices and users login to the Windows desktop using their Azure AD identity. The login is performed using "Windows Hello for Business" which supports a wide variety of auth methods, nearly all of which provide - as part of the authentication - an "MFA Claim" within the Primary Refresh Token (PRT). What I don't know yet is whether the MFA claim generated is accepted when IDP requests an MFA event. CrowdStrike had to fudge a few things to "trigger" an MFA in Azure AD as I understand it. Prior to this they needed an NPS server which we were not keen on. We are cloud-first, so if a vendor says "you need to deploy a server" we push back pretty hard. The better question is whether FIDO2 keys are supported. FIDO2 keys require an on-the-desktop interaction, so my belief here - yet to be validated - is that it will use Phone Sign-In MFA, not FIDO2 support. More on reddit.com
Videos
04:11
See Falcon Next-Gen Identity Security in Action - YouTube
01:33
Falcon Identity Protection Real-Time Entra ID Login Protection ...
02:23
Falcon Identity Protection Secure Your Cloud Identity Environment: ...
02:12
Falcon Identity Protection Unified Identity Protection for Hybrid ...
02:35
Securing Non-Human Identities with Falcon Identity Protection - ...
CrowdStrike
crowdstrike.com › platform › next-gen identity security › caep
Continuous Access Evaluation | CrowdStrike Falcon® Identity Protection
August 13, 2025 - Falcon Identity Protection quickly establishes baselines for user behavior and detects suspicious activity in real time. It enhances threat detection accuracy and reduces the time to identify and respond to identity threats.
Reddit
reddit.com › r/crowdstrike › falcon identity threat protection (itp) risk factors descriptions
r/crowdstrike on Reddit: Falcon Identity Threat Protection (ITP) Risk factors descriptions
January 10, 2024 -
We just integrated Falcon ITP with our SIEM, and we are receiving events that categorize risks in the following types:
WEAK_PASSWORD_POLICY
INSUFFICIENT_PASSWORD_ROTATION
STALE_ACCOUNT
...
(I don't want to publish all of them, as I don't know if these information is public.)
Some of the names are descriptive enough, but I´d like to have a bigger picture of what they mean. ¿Is there a site where this information is available? I have not found it.
Top answer 1 of 3
1
Hey new poster! We require a minimum account-age and karma for this subreddit. Remember to search for your question first and try again after you have acquired more karma. I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
2 of 3
1
You can find a description of the risk factors in the online documentation. Identity Protection and MFA > Identity Monitoring > Identity-based Incidents, Detections, and Risks > Appendix B: Risk Factors. You can also find a user or device with one of these risk factors in the console and if you navigate to the Risk section, it explains the risk and provides recommended actions.
Cloudprotectionworks
cloudprotectionworks.co.uk › Falcon-ITP.php
CrowdStrike Falcon Identity Threat Protection | CloudProtectionWorks.co.uk
CrowdStrike Falcon Identity Threat Protection enables hyper accurate threat detection and real-time prevention of identity-based attacks combining the power of advanced AI, behavioral analytics and a flexible policy engine to enforce risk-based conditional access.
AWS Marketplace
aws.amazon.com › marketplace › pp › prodview-coqbkblyhbdi4
AWS Marketplace: CrowdStrike Falcon Identity Protection
Perfect for organizations that ...ection/falcon-zero-trust/ Falcon Identity Threat Detection: Realize deeper visibility for identity-based attacks and anomalies in real time without requiring ingestion of log files....
ServiceNow Store
store.servicenow.com › store › app › e9e8e72e1be06a50a85b16db234bcb3d
CrowdStrike Falcon Identity Protection - ServiceNow Store
CrowdStrike Falcon® Identity Threat Detection (ITD) offers Active Directory Security visibility into all account types with insights and analytics, and detects identity-based attacks or anomalies by comparing live authentication traffic against baseline behaviors and attack patterns.
YouTube
youtube.com › watch
See Falcon Identity Protection in Action - YouTube
Adversaries increasingly target identity, with 80% of modern breaches involve stolen credentials. Watch to see how Falcon Identity Protection stops these thr...
Published February 8, 2025
Digital Marketplace
assets.applytosupply.digitalmarketplace.service.gov.uk › g-cloud-13 › documents › 93536 › 945803463294602-service-definition-document-2022-05-05-0915.pdf pdf
FALCON - IDENTITY PROTECTION CR OWD S TR IKE
Falcon® Identity Protection solution can offer the information and assistance you need to pass audits · and stop modern attacks like ransomware and supply chain threats.
Digital Marketplace
applytosupply.digitalmarketplace.service.gov.uk › g-cloud › services › 182469044026457
CrowdStrike Falcon Identity Protection - Digital Marketplace
Falcon Identity Protection unifies endpoint and identity security with a single agent and console for immediate time-to-value.
Dell Technologies
delltechnologies.com › asset › en-us › solutions › business-solutions › technical-support › falcon-identity-threat-protection-datasheet.pdf pdf
Dell SafeGuard and Response CrowdStrike Falcon® Identity Threat Protection
hybrid identity stores without the need for complex, string-based queries. Choose from a list of pre-defined search · criteria, including authentication events, use of unencrypted protocols, user roles, IP reputation, risk scores and many · more. If required, create and save your own search criteria to proactively sift through raw events and email them as ... Comprehensive API coverage: Extend the CrowdStrike Falcon platform’s risk score and high-fidelity information to
The Globe and Mail
theglobeandmail.com › investing › markets › stocks › CRWD-Q › pressreleases › 33745492 › palo-alto-plans-cyberark-buyout-can-this-boost-panw-s-identity-edge
Palo Alto Plans CyberArk Buyout: Can This Boost PANW's Identity Edge? - The Globe and Mail
July 30, 2025 - However, identity-driven threat protection has remained a weaker link, an area where competitors like CrowdStrike Holdings, Inc.CRWD and Okta, Inc.OKTA have moved more aggressively. Okta focuses solely on identity, while CrowdStrike is pushing deeper into identity protection with native offerings such as Falcon Identity Threat Protection, Falcon Identity Threat Detection and Falcon Privileged Access.